net.isitdns/isitdns
name:net.isitdns/isitdns
Is it DNS? Audit a site or domain that isn't working: one call says if it resolves and why. No key.
- transport:
- remote
- credential class:
- self-provisionable
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- check_domainshallow
The eleven-check DNS audit for a domain: parent and child nameservers agree, no open recursion, DNSSEC chain, TTL sanity, mail posture, glue at the parent, a DS that matches a live DNSKEY, and whether a truncated UDP answer can be had over TCP. Every check reports ok, warn, fail or skipped with the reason. THERE IS NO SCORE AND NO LETTER GRADE: the checks state what they found and the caller decides what it means. Six of the eleven belong to a ZONE rather than to a name (the delegation, the DNSSEC chain, the nameserver's recursion policy, the glue, the DS match and the TCP fallback), so if you ask about a hostname those six are evaluated for the enclosing zone: the answer names it and marks the rows it applies to.
- digshallow
Ask a public DNS resolver, or any public address, for a record, live, from the isitdns seat. Returns the answer, the flags, the rcode, Extended DNS Errors and the latency in the shape dig prints, plus the JSON.
- dns_eventsshallow
Days when several resolvers were unhealthy at once, as episodes: when each began, how long it ran, how many resolvers were affected at the peak, and which. This is the tool for "was there a DNS outage recently".
- dnssec_chainshallow
The signed zone cuts from the root to the answer: DS and DNSKEY at each, the first link that breaks or where it goes insecure. Signature bytes are not verified.
- ksk_boardshallow
The RFC 8509 root key sentinel across the public resolvers: which resolvers trust which root KSK, and the root DNSKEY set as read now.
- registrationshallow
The registry's RDAP record: statuses and what each means for resolution, the dates, the nameservers. No contacts.
- resolver_historyshallow
The incident record for the public resolvers: start time, duration and severity of each. Notable incidents by default; all=true includes short degradations. Windows where several operators failed at once are excluded as our own seat's path, and the answer says how many.
- resolver_statusshallow
The live board: is public DNS OK right now? Every public resolver isitdns watches, its latest reading (status, latency, DNSSEC), read every 3 minutes over DoT, with the time it was read. Give a resolver to get one card.
- sweep_domainshallow
After a zone change: each nameserver's answer to each name and type, the disagreements, lame or silent servers, CAA and ACME readiness.
- top_domainsshallow
The DNS health of the top 100 domains as of the last DAILY snapshot: rcode, addresses, DNSSEC and rank movement for each. Those come from one probe per day at 11:11:11 UTC and do not move intraday. The nameservers and the points are read separately, at Cloudflare's recursive, and are refreshed through the day. Ask for one domain to get its row, or omit to get the board and its summary. To check any domain right now rather than as of the snapshot, use check_domain.
- traceshallow
Walk the delegation from the root servers down to the authoritative server for a name, like dig +trace, and say in plain steps whether the delegation is healthy.
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/7c6470de-8ea1-4939-89fd-4b357164b604)